PT-2026-41793 · Packagist · Sulu/Sulu

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-45701

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Impact

The password reset tokenand API key generation uses a weak cryptographical hash algorithm.

Patches

Fixed in 2.6.23 and 3.0.6 version.

Workarounds

Patch the related User.php and ResettingController.php file in the SecurityBundle.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2026-45701
GHSA-7FV8-6PP7-6H85

Affected Products

Sulu/Sulu